Cybersecurity analysts monitor digital threats and cloud infrastructure on a high-tech operations dashboard.
Hiscox’s Cyber Readiness Report 2026 puts a hard number on a reality many small-business IT teams already recognize: cyber incidents are being budgeted like recurring operating costs. The insurer’s survey found that 29% of responding organizations suffered at least one successful cyberattack in the previous 12 months, with affected firms reporting four successful incidents on average, about 32.8 hours of disruption, and a reported global average cost of $52,602.

The useful takeaway is not that an SMB can forecast its next breach to the dollar. It is that security planning built around “prevent every incident” leaves a business unprepared for the predictable operational work after prevention fails: isolating endpoints, restoring identities and data, investigating logs, communicating with customers, and keeping essential services running. For Windows administrators, that makes tested recovery capability as material as endpoint protection and patch compliance.

Petri’s report on the findings correctly identifies the shift toward resilience. But the underlying Hiscox data carries limitations that should change how executives read the headline numbers. This is a survey commissioned by a cyber insurer, conducted by Wakefield Research from June 5 through June 17, 2026, among 6,800 cybersecurity decision-makers at organizations with fewer than 250 employees in the United States, United Kingdom, and eight European markets. It is evidence about surveyed small and midsize businesses—not a census of all companies, and certainly not a universal cyber-loss benchmark.

The average figures should not become a budget formula​

Hiscox reports that businesses spend an average of roughly $51,000 annually on cyber resilience while cyber incidents cost an average of about $52,602. On its face, that looks like a near one-to-one balance between security spending and loss. It is not proof that spending $51,000 will limit a company’s losses to $52,602, or that the two figures describe the same group of companies and costs.

The report uses slightly different language in different places. Its main narrative says cyber incidents cost organizations around $52,000 annually, while the accompanying chart calls $52,602 the “average cost of attack.” The web summary describes 32 hours of operational downtime “for every hack,” while the PDF labels the figure simply as average downtime. Hiscox does not provide a public calculation table that lets readers determine exactly which expenses were counted, whether costs are self-reported estimates, or how repeated incidents were weighted.

That does not invalidate the survey. It does mean the numbers are best treated as a signal of exposure and disruption, rather than an actuarial model for setting an IT budget. A business with a cloud email outage, an isolated phishing incident, and a full ransomware event can all say it experienced a cyberattack, yet their recovery timelines and costs will be radically different.

The 29% figure also masks sharp country variation. Hiscox says the attack rate was 38% in the UK but 20% in the United States; Italy had the highest reported average attack cost, at $134,138. Those differences reinforce a basic planning rule: local regulation, dependence on managed providers, industry, company size, and the systems that must remain available matter more than a global average.

Hiscox itself warns against decade-to-decade comparisons​

The insurer frames the 2026 survey as the tenth edition of a long-running readiness report and contrasts this year’s 29% attack rate with 57% in its 2017 data. That apparent improvement is tempting to celebrate, particularly after the higher attack rates reported in some earlier editions.

But the 2026 PDF explicitly says its historical findings are not directly comparable because survey scope and methodology changed. That caveat deserves more prominence than the “then versus now” graphic. Changes to countries surveyed, respondent selection, questions, definitions, and the line between attempted and successful attacks can produce large swings in reported rates without proving that the threat environment itself rose or fell by the same amount.

There is a practical reason to care about this distinction. An executive who sees a headline suggesting attacks have nearly halved over a decade may conclude that existing controls are sufficient. The operational evidence in the same report points in the opposite direction: affected organizations reported repeated successful incidents, staffing and external-expertise costs, delayed expansion projects, lost opportunities, financial penalties, and reputational damage.

Infosecurity Magazine’s coverage of the report also highlighted the four-incident average among businesses that had suffered an attack. That is the more consequential number for IT operations. The cost of an incident is rarely limited to the first containment call. It can reappear as mandatory password resets, renewed endpoint deployment, mailbox investigations, tenant hardening, legal review, customer notification, insurance claims, and a backlog of delayed projects.

Recovery time has to be engineered before the incident​

A reported 32.8 hours of disruption is not simply a measure of attacker capability. It is often a measure of how well an organization understands its own dependencies. If a business cannot quickly identify which Entra ID accounts are privileged, which servers hold line-of-business data, which backups can be restored cleanly, and which third-party applications depend on those identities, the outage clock keeps running after the malicious process is removed.

For Windows and Microsoft 365 environments, resilience work should produce evidence, not policy documents. Teams should be able to demonstrate that privileged accounts use phishing-resistant multifactor authentication where feasible; that emergency access accounts are secured and tested; that endpoint, identity, firewall, email, and cloud audit logs can be correlated; and that a compromised device can be isolated without waiting for a vendor case to be opened.

Backup strategy needs the same level of scrutiny. “We have backups” does not answer whether the backups are protected from administrative compromise, whether retention survives an attacker’s deletion attempts, whether Microsoft 365 data is recoverable at the needed granularity, or whether a restored application can actually authenticate and resume operations. CISA’s small-business guidance specifically recommends automatically backing up critical data and system configurations, keeping copies retrievable and separated from the organizational network, while also requiring MFA and limiting administrative access.

NIST’s current incident-response guidance, Special Publication 800-61 Revision 3, also pushes organizations to integrate preparation, detection, response, and recovery into broader cybersecurity risk management. The change in emphasis is important: incident response is not a binder retrieved after ransomware. It is a capability sustained through asset management, monitoring, access control, vendor arrangements, backups, exercises, and post-incident improvement.

The practical test is whether essential work can continue​

Hiscox says 62% of respondents are updating employee cybersecurity training, 55% are hiring additional cybersecurity staff, and 51% are investing in new tools. Those can be sensible investments, but neither a training campaign nor another dashboard establishes resilience on its own.

An SMB’s IT lead should use the report as a prompt to run a business-impact exercise with finance and operations. Identify the applications that stop revenue, customer service, payroll, fulfillment, production, or regulated work; establish recovery-time and recovery-point targets for each; then test whether current Windows, cloud, identity, network, and backup arrangements meet those targets. The output should include named decision-makers and outside contacts, not merely technical steps.

A short restoration exercise is more revealing than an annual tabletop session alone. Restore a critical server or workload to a segregated environment. Recover a deleted mailbox or SharePoint library. Simulate a compromised administrator account. Verify that log sources remain available and that the response team can reach legal, communications, cyber-insurance, managed-service, and incident-response contacts without relying on the compromised environment.

Hiscox reports that 32% of surveyed companies now link executive compensation or performance measures to cybersecurity outcomes after an attack. Whether or not an organization adopts that approach, the larger message is sound: cyber risk cannot remain an IT department’s isolated scorecard when a breach can stall commercial decisions and disrupt core work for days.

The defensible budget conversation is therefore not whether a business can afford a recurring cyber-resilience expense. It is whether it has defined the cost of losing email, identity, endpoints, line-of-business systems, and customer data—and whether it has rehearsed the recovery required to keep the business operating when one of those systems fails.